+49 (0) 821 / 80 99 46 - 0
+49 (0) 821 / 80 99 46 - 0
Request call-back
Contact us
Report a claim
exali.com My business. My insurance.
My exali login
exali.com
  • Insurance

    Professional Indemnity

    Professional Indemnity Insurance for Digital Professions

    General

    Professional Indemnity Insurance
    General Liability Insurance
    Financial Losses Insurance

    More Information

    Selected Professions
    Glossary
  • News & Stories
  • Blog
  • Product finder
    Product finder
  • My exali login
  • Report a claim
"Reliable information for your Latvian business - because Google doesn’t have all the answers"
Anja Pikowski
Online Marketing
Anja Pikowski,Online Marketing
My business. My insurance.
Anja Pikowski
Online Marketing
Anja Pikowski,Online Marketing

Already in?

With our Newsflash, you benefit from the latest news and topics relating to your business every month:

  • Tips, information and expert interviews
  • Real damage events
  • Legal matters and dangers of warnings
The perfect support for your success.

Home / News&Stories /
Real Exali Damage Event: Cyber Criminals Turn Consulting Firm into Bitcoin Mine!
Hacker Attack on Consulting Firm

Real Exali Damage Event: Cyber Criminals Turn Consulting Firm into Bitcoin Mine!

Post by Ines RietzlerPost by Ines RietzlerAuthor
Post by Ines RietzlerPost by Ines RietzlerAuthor
Friday, 28 January 2022
Friday, 28 January 2022
Back to the overview

Digital currencies have been popular even before Elon Musk started hyping them. While not everyone understands how Bitcoin, Dodgecoin and so on work, most of us have heard of them before. Bitcoin mining, the production of bitcoins so to speak, is also a term most people are familiar with by now. Hopefully your business has never become the centre of a Bitcoin mining operation without your knowledge. But it did happen to the consulting firm in this real exali damage event...

Cryptocurrency: Cash for the Internet

Cryptocurrencies are a hype that doesn’t seem to be stopping. Bitcoin, Litecoin, Ethereum, Stellar, Dodgecoin: All of these terms refer to digital means of payment, or “cryptocurrencies”. They are also a payment network that is operated only by the users themselves and without a central authority (such as banks or authorities) or intermediaries. From the users' point of view, Bitcoin is the cash for the internet, so to speak.

What is Bitcoin Mining?

Bitcoin mining is the process of earning bitcoins by providing computing power - one could call it "digital gold mining". The computing power is required to process Bitcoin transactions, secure data and synchronise the users in the network. Bitcoin mining is thus a kind of Bitcoin data centre operated by "miners" worldwide.

Hackers Use Computing Power for Illegal Bitcoin Mining

The scene of this real damage event is a company that actually specialises in management consulting and has absolutely nothing to do with Bitcoin mining. Our at least it didn’t, until the wee hours of one fateful day when hackers got into the company’s system. At this early stage there were no employees in the office.

The cyber criminals cracked the administrators’ access code, hacked into the company’s computer system and installed a Bitcoin miner on the server. So the entire computing power of the server was used to mine Bitcoin.

Locked Out of their Own System by Cyber Criminals 

The attack only came to light a day later, when employees from the accounting department of the consulting firm tried to download documents from the banking software. Suddenly they no longer had access to the system and the task manager couldn’t be started either. The system was completely paralysed. The company hired an IT specialist to find out what the problem was. Fortunately, he immediately recognised what had happened, shut down the system and removed the virus.

Nevertheless, the company was only able to work to a very limited extent for several days. It wasn’t just the employees in the accounting department who didn’t have access to the system, the consultants were locked out too, which of course led to delays in processing customer orders and appraisals. 

The full extent of the attack and the amount of damage is still unclear. The insurer has already confirmed that it will assume the costs for the damage. This at least means the company won’t be left to cover the costs themselves and can now use their computers for their actual business, advising their customers.

Illegal Crypto Mining: New Scam from Cyber Criminals

Everyone is at risk of cyber criminals using their computers as a production facility for Bitcoin or other cryptocurrencies. That’s because this new source of income is very popular with hackers. The hackers don't have to put in a lot of effort to do this either. They hack into private or company computers and install a program in the background that hijacks the computer’s computing power and uses it for mining.

Users usually don’t notice the attack because the perpetrators often do not even have to block the computer completely. Some people only realise that something is wrong with the IT when their electricity bill goes up, since Bitcoin mining requires a lot of computing power and associated energy. One particularly problematic thing is that some hackers use security holes in the operating system to gain access to the servers.

Modern Protection against New Risks

The consulting company in this case was fortunately aware of the risk of a hacker attack in advance and chose exali Professional Indemnity Insurance with the modern “First-Party Cyber and Data Risks Insurance (FPC)”add-on. This add-on means consultants are optimally protected beyond their basic Professional Indemnity Insurance if their own computer systems are damaged by hacker attacks, DDoS attacks or data theft. The insurance company will then cover the costs of restoring the systems (for example, for computer forensics specialists or specialised lawyers).

Since the risk of a cyberattack – whether its Bitcoin mining, ransomware or a virus – exists for every business, the “First-Party Cyber and Data Risks Insurance (FPC)” add-on is available for every industry.

Calculate your premium:

cancel
Yes, delete
Your annual net turnover (last 12 months)
<span class='visible--desktop'>First-Party Cyber and Data Risks Insurance (FPC)</span> <span class='visible--tablet'>First-Party Cyber and Data Risks Insurance (FPC)</span> <span class='visible--mobile'>FIrst-Party Cyber and Data Risks Insurance (FPC)</span>
<span class='visible--desktop'><p><strong>This add-on protects your business from the risk of hacking, DDoS attacks or other internet crime.</strong></p> <p>Reimbursed/covered:<strong> </strong>for example costs for the <strong>restoration of your IT systems</strong>, the commissioning of professional <strong>computer forensics analysts</strong> or specialised <strong>lawyers</strong> (including criminal defence) as well as for <strong>crisis management &amp; PR</strong>. Additional costs for the quick elimination or avoidance of an interruption to your business are also insured.</p> <h5>Further Examples of Damages We Insure</h5> <ul class="liste"> <li>Damage to your own IT systems (from hacking)</li> <li>First-party data rights claim (in particular spying on personal data)</li> <li>Expenses for an (imminent) interruption of business (additional cost coverage)</li> <li>Breach of trust damage (intentional damage to own IT by employees)</li> <li>Costs for criminal defence (internet criminal legal protection)</li> </ul> <h5>Insurer Services</h5> <p>The special benefit about this add-on is the assumption of your own <strong>costs</strong>, e.g. for the commissioning of:</p> <ul class="liste"> <li>Computer forensics specialists</li> <li>Specialised lawyers</li> <li>Consultants to provide information to data owners</li> <li>Professionals for PR &amp; crisis management</li> <li>Credit protection and monitoring services</li> </ul> <p>as well as the assumption of <strong>additional costs, e.g. for the use of third-party IT and computer systems.</strong></p> </span> <span class='visible--tablet'><p><strong>This add-on protects your business from the risk of hacking, DDoS attacks or other internet crime.</strong></p> <p>Reimbursed/covered:<strong> </strong>for example costs for the <strong>restoration of your IT systems</strong>, the commissioning of professional <strong>computer forensics analysts</strong> or specialised <strong>lawyers</strong> (including criminal defence) as well as for <strong>crisis management &amp; PR</strong>. Additional costs for the quick elimination or avoidance of an interruption to your business are also insured.</p> <h5>Further Examples of Damages We Insure</h5> <ul class="liste"> <li>Damage to your own IT systems (from hacking)</li> <li>First-party data rights claim (in particular spying on personal data)</li> <li>Expenses for an (imminent) interruption of business (additional cost coverage)</li> <li>Breach of trust damage (intentional damage to own IT by employees)</li> <li>Costs for criminal defence (internet criminal legal protection)</li> </ul> <h5>Insurer Services</h5> <p>The special benefit about this add-on is the assumption of your own <strong>costs</strong>, e.g. for the commissioning of:</p> <ul class="liste"> <li>Computer forensics specialists</li> <li>Specialised lawyers</li> <li>Consultants to provide information to data owners</li> <li>Professionals for PR &amp; crisis management</li> <li>Credit protection and monitoring services</li> </ul> <p>as well as the assumption of <strong>additional costs, e.g. for the use of third-party IT and computer systems.</strong></p> </span> <span class='visible--mobile'><p>Protection against hacking damage to your own IT systems, DDoS attacks, computer misuse, theft of data carriers and other data rights violations and the majority of the resulting expenses and costs.</p> </span> <div class="spaceTop-20"> <div>If you have any further questions, our customer service is happy to help.</div> <div id="rechnerKontaktForm" class="spaceTop-10"> <div class="col-grid col-grid--flush"> <div class="visible--mobile"> <div id="rkfPhone" class="service-item service-item--phone col col--10 text--center no-margin"> <a href="tel:+498218099460" class="rkfPhone--nr" data-eventpush="eventPush_phone_info"> +49 (0) 821 / 80 99 46 - 0 </a> </div> <div class="col col--2 no-margin no-padding position-relative"> <button type="button" class="close modal-info__close" data-dismiss="modal" aria-hidden="true"></button> </div> </div> <div class="hidden--mobile"> <div class="rechnerKontaktForm--no-mobile"> <div id="rkfCallback" class="service-item service-item--callback col col--tablet--4 no-margin"> <span data-eventpush="eventPush_callback_info"> Request call-back </span> </div> <div id="rkfMail" class="service-item service-item--mail col col--tablet--4 text--center no-margin"> <span data-eventpush="eventPush_mail_info"> Contact us </span> </div> <div id="rkfPhone" class="service-item service-item--phone col col--tablet--4 text--right no-margin"> <a href="tel:+498218099460" data-eventpush="eventPush_phone_info"> +49 (0) 821 / 80 99 46 - 0 </a> </div> </div> </div> </div> </div> <div class="hidden--mobile"> <div class="infoKontaktForm"></div> <div class="text--right cursor-pointer spaceTop-10"> <a data-dismiss="modal" aria-hidden="true">Close</a> </div> </div> </div>
<span class='visible--desktop'>Engineering Activities (ENG)</span> <span class='visible--tablet'>Engineering Activities (ENG)</span> <span class='visible--mobile'>Engineering Activities (ENG)</span>
<span class='visible--desktop'><p><strong>If you provide engineering services exclusively or in addition to IT/telecommunications, you can insure the liability risks with the &bdquo;Engineering Activities&ldquo; endorsement.</strong></p> <p>The Engineering Activities extension provides&nbsp;<strong>blanket coverage</strong>. This means that all engineering activities are covered without the need for listing each and every activity. Those listed in the engineering endorsement are therefore merely illustrative examples:</p> <ul class="liste"> <li>Hardware and software development for machinery and plant, embedded software</li> <li>Machinery and plant testing, commissioning support</li> <li>Quality management and assurance</li> <li>Technical drawing, CAD, CAM</li> <li>Technical management consultancy, in particular purchasing, strategy, process design, activities as expert</li> </ul> <h5>Requirements for Engineering Insurance</h5> <ul class="liste"> <li>You <strong>do not provide engineering services</strong>, plants, machinery or associated parts and/or <strong>planning</strong>.</li> <li>You provide engineering products <strong>in a supporting and/or advisory capacity</strong> and are not responsible fort he final engineering product.</li> <li>No machines, systems, engineering products or other parts shall be put &nbsp;into series production directly / &nbsp;<strong>without approval and acceptance</strong> by the principal (keyword: final sign-off).</li> </ul> <h5>Deductible</h5> <p>The deductible for financial loss and property damage is the same as the deductible selected for the financial loss insurance (FLI).</p> <p>For more information, please refer to <strong>Section A.7 &quot;Engineering Activities (ENG)&quot;</strong> of the Insurance Conditions.</p> </span> <span class='visible--tablet'><p><strong>If you provide engineering services exclusively or in addition to IT/telecommunications, you can insure the liability risks with the &bdquo;Engineering Activities&ldquo; endorsement.</strong></p> <p>The Engineering Activities extension provides&nbsp;<strong>blanket coverage</strong>. This means that all engineering activities are covered without the need for listing each and every activity. Those listed in the engineering endorsement are therefore merely illustrative examples:</p> <ul class="liste"> <li>Hardware and software development for machinery and plant, embedded software</li> <li>Machinery and plant testing, commissioning support</li> <li>Quality management and assurance</li> <li>Technical drawing, CAD, CAM</li> <li>Technical management consultancy, in particular purchasing, strategy, process design, activities as expert</li> </ul> <h5>Requirements for Engineering Insurance</h5> <ul class="liste"> <li>You <strong>do not provide engineering services</strong>, plants, machinery or associated parts and/or <strong>planning</strong>.</li> <li>You provide engineering products <strong>in a supporting and/or advisory capacity</strong> and are not responsible fort he final engineering product.</li> <li>No machines, systems, engineering products or other parts shall be put &nbsp;into series production directly / &nbsp;<strong>without approval and acceptance</strong> by the principal (keyword: final sign-off).</li> </ul> <h5>Deductible</h5> <p>The deductible for financial loss and property damage is the same as the deductible selected for the financial loss insurance (FLI).</p> <p>For more information, please refer to <strong>Section A.7 &quot;Engineering Activities (ENG)&quot;</strong> of the Insurance Conditions.</p> </span> <span class='visible--mobile'><p>The Engineering Activities extension provides&nbsp;<strong>blanket coverage</strong>.</p> <h5>Requirements for Engineering Insurance</h5> <ul class="liste"> <li>You <strong>do not provide engineering services</strong>, plants, machinery or associated parts.</li> <li>You provide engineering products <strong>in a supporting and/or advisory capacity</strong>.</li> <li>No machines, systems, engineering products or other parts shall be put &nbsp;into series production directly/<strong>without the client&#39;s approval</strong> (final sign-off).</li> </ul> <h5>Deductible</h5> <p>Same as the deductible selected for the financial loss insurance (FLI).</p> </span> <div class="spaceTop-20"> <div>If you have any further questions, our customer service is happy to help.</div> <div id="rechnerKontaktForm" class="spaceTop-10"> <div class="col-grid col-grid--flush"> <div class="visible--mobile"> <div id="rkfPhone" class="service-item service-item--phone col col--10 text--center no-margin"> <a href="tel:+498218099460" class="rkfPhone--nr" data-eventpush="eventPush_phone_info"> +49 (0) 821 / 80 99 46 - 0 </a> </div> <div class="col col--2 no-margin no-padding position-relative"> <button type="button" class="close modal-info__close" data-dismiss="modal" aria-hidden="true"></button> </div> </div> <div class="hidden--mobile"> <div class="rechnerKontaktForm--no-mobile"> <div id="rkfCallback" class="service-item service-item--callback col col--tablet--4 no-margin"> <span data-eventpush="eventPush_callback_info"> Request call-back </span> </div> <div id="rkfMail" class="service-item service-item--mail col col--tablet--4 text--center no-margin"> <span data-eventpush="eventPush_mail_info"> Contact us </span> </div> <div id="rkfPhone" class="service-item service-item--phone col col--tablet--4 text--right no-margin"> <a href="tel:+498218099460" data-eventpush="eventPush_phone_info"> +49 (0) 821 / 80 99 46 - 0 </a> </div> </div> </div> </div> </div> <div class="hidden--mobile"> <div class="infoKontaktForm"></div> <div class="text--right cursor-pointer spaceTop-10"> <a data-dismiss="modal" aria-hidden="true">Close</a> </div> </div> </div>
Yes, switch to {{targetDomain}}
You indicated that your headquarter is in {{targetCountry}}. So we will redirect you to the corresponding version of exali, {{targetDomain}}. Settings that have been made may not be transferred. The premium and scope of the insurance policies offered may vary slightly depending on the country.
Would you like to switch to {{targetDomain}}?
No, stay on {{currentDomain}}
You indicated that your headquarter is in {{targetCountry}}. So we will redirect you to the corresponding version of exali, {{targetDomain}}. Settings that have been made may not be transferred. The premium and scope of the insurance policies offered may vary slightly depending on the country.
Would you like to switch to {{targetDomain}}?
Yes, switch to {{targetDomain}}
No, stay on {{currentDomain}}
please wait ...

Ines Rietzler
Author profile
Ines Rietzler
Formerly Chief Editor

Who am I?
After a traineeship and a few years in corporate communications, I now work at exali as editor-in-chief of the online editorial department and am responsible for all content.
What do I enjoy?
Summer, travel, good food and football.
What do I dislike?
Travel by train, Brussels sprouts and slime.

Author profile
Ines Rietzler
Ines Rietzler

Formerly Chief Editor

Who am I?
After a traineeship and a few years in corporate communications, I now work at exali as editor-in-chief of the online editorial department and am responsible for all content.
What do I enjoy?
Summer, travel, good food and football.
What do I dislike?
Travel by train, Brussels sprouts and slime.

Previous article
 
Back
 
Next article
These articles might also interest you
A Real-Life exali Damage Event: Forgotten Confirmation Causes 4.000 Euros Damage
A Real-Life exali Damage Event: Forgotten Confirmation Causes 4.000 Euros Damage
Data Protection: 2021 is the Year with the Highest Fines to Date
Data Protection: 2021 is the Year with the Highest Fines to Date
Consulting on Street Lighting: Consulting Firm to Pay 20.000 Euros in Compensation
Consulting on Street Lighting: Consulting Firm to Pay 20.000 Euros in Compensation
How Faulty Software Resulted in Hundreds of Innocent Employees Ending Up in Jail
How Faulty Software Resulted in Hundreds of Innocent Employees Ending Up in Jail
These articles might also interest you
A Real-Life exali Damage Event: Forgotten Confirmation Causes 4.000 Euros Damage
A Real-Life exali Damage Event: Forgotten Confirmation Causes 4.000 Euros Damage
Data Protection: 2021 is the Year with the Highest Fines to Date
Data Protection: 2021 is the Year with the Highest Fines to Date
Consulting on Street Lighting: Consulting Firm to Pay 20.000 Euros in Compensation
Consulting on Street Lighting: Consulting Firm to Pay 20.000 Euros in Compensation
How Faulty Software Resulted in Hundreds of Innocent Employees Ending Up in Jail
How Faulty Software Resulted in Hundreds of Innocent Employees Ending Up in Jail
0 Comments
Write a comment
Please fill in all areas marked as * required fields.

By clicking the ‘Send’ button, the data entered in the above form will be collected and processed for the purpose of processing your request. All data is transmitted in encrypted form and only processed within the scope of the information in the data protection information. You have a right of objection with effect for the future.

Insurance

  • Professional Indemnity for Digital Professions
  • Selected Professions
  • Report damage event

News & Stories

  • Articles
  • Videos
  • Glossary
  • Subscribe to Newsletter

About us

  • About exali
  • Jobs
  • Contact us
  • Imprint
  • Data Protection Declaration
  • Right of withdrawal
© exali AG, all rights reserved
Unfortunately, your web browser is out of date! Please update your browser in order to be able to use all functions in the premium calculator.
Choose the location of your headquarter
Depending on your country, the insurance offered by exali may vary slightly. Please select the country where you have your headquarter to get the offer that suits you best.